Subscription-based access to Entrust nShield HSM services, delivering the security of on‑premises HSMs with the flexibility of cloud deployment
nSaaS is a subscription-based, post-quantum ready solution for generating, accessing, and protecting cryptographic key material—separately from sensitive data—using FIPS‑certified nShield HSMs delivered as a cloud service.
Because nShield as a Service benefits from the same unique Security World architecture as on-prem nShield deployments, you can easily migrate your cryptographic operations from on-prem to the cloud, or use a hybrid approach, mixing both cloud-based and on-prem nShield HSMs for increased redundancy and reliability.
Today's enterprises seek the flexibility of cloud deployments. However, when the HSMs acting as your trust anchors reside in your datacenter, access from your cloud applications becomes complex and expensive. With nSaaS your applications can access your HSMs from anywhere—your datacenter, your cloud deployments, or both—while benefiting from:
Regional data centers facilitate geo-fencing to meet cloud data security and data sovereignty mandates.
Advance your cloud-centric strategies with FIPS 140-2 Level 3 protection for your business-critical apps and data.
Supports multi-cloud/hybrid deployments with the same consistent toolset. Flexibility to migrate workloads on premises or to another Cloud Service Provider.
The CodeSafe secure execution capability provides on-demand access to your organization's secure, sensitive code protected inside the HSM.
Full specifications for nShield as a Service
| Specification | Details |
|---|---|
| Connectivity |
|
| Security Compliance: |
|
| Safety and Environmental Standards Compliance: | UL, CE, FCC, RCM |
| Canada ICES | RoHS2, WEEE, Data Center Certifications |
| Supported APIs | PKCS#11, OpenSSL, Java (JCE), Microsoft CAPI/CNG |
| Supported Cryptographic Algorithms | Asymmetric public key algorithms: RSA, Diffie-Hellman, ECMQV, DSA, KCDSA, ECDSA, ECDH, Edwards (X25519, Ed25519ph) |
| Secp256k1, | NIST standardized post‑quantum algorithms: ML‑DSA(44, 65, 87), ML‑KEM(512, 768, 1024) |
| Specifications | Symmetric algorithms: AES, AES-GCM, ARIA, Camellia, CAST, RIPEMD160 HMAC, SEED |
| Triple DES | Hash/message digest: SHA-1, SHA-2 (224, 256, 384, 512 bit) |
| HAS-160 | Full Suite B implementation with fully licensed ECC including Brainpool and custom curves, nShield HSMs offers support for the majority of these cryptographic algorithms as part of the standard feature set. For organizations wishing to use ECC or South Korean algorithms, optional activation licenses are needed., Supported Platforms |
Download product documentation and resources
Explore other configurations and models that might suit your needs.
Our team of experts is ready to help you find the perfect solution for your business needs. Get personalized advice and competitive quotes.
We're here to help with any questions